Tech • AI • Robotics • Game

VIDEO
ENFR

We hosted the researcher tracking teenage millionaires

5/10
AIUnderscore_September 21, 2026 at 12:31 PM32:11
Audio player
0:00 / 0:00

TL;DR

Automated sneaker bots have turned limited-edition retail into a lucrative arms race, snapping up shoes, streetwear and tickets in seconds and fueling a resale market worth about €300 million.

KEY POINTS

A market built on scarcity

Limited releases, known as drops, are designed to create urgency and scarcity around products such as Nike sneakers, Supreme clothing, collectible figurines and concert tickets. That scarcity has fostered a resale economy in which sought-after items can disappear within minutes and reappear at sharply higher prices.

Teenagers and young resellers are active players

The trade often attracts very young participants, sometimes as young as 15 or 16, many of whom begin as enthusiasts trying to secure products for themselves. Some then realize the same tools can generate steady income through resale.

Bots are usually bought, not built

Most resellers do not code their own tools. They buy or rent ready-made software configured to monitor release pages, detect product IDs, select sizes, automate checkout, rotate accounts and use proxy networks to mask IP addresses. A bot can cost €300 to €400 upfront, plus €200 to €300 a month, before adding proxy bills and paid access to insider release groups.

Profit margins can be extreme

A single pair of Jordan sneakers bought for about €200 can resell for €500 to €700, a multiplier of 2.5 to 4. For operators landing multiple pairs across repeated drops, the gains can reach several thousand euros a month, though many also lose money on failed attempts and infrastructure costs.

The real money may be in selling tools

Developers who build bypass services, anti-captcha tools or bot infrastructure often earn more reliably than resellers. Some one-person operations selling access tokens or anti-detection services can reportedly generate more than €90,000 a month in revenue with limited overhead.

One bot reportedly processed enormous volumes

A widely used bot linked to the market was said to have enabled more than $20 million in purchases during a single sale in 2018. By 2025, it was reportedly handling around 500,000 successful checkouts in a year, representing roughly €300 million in purchases of shoes and other limited items.

Why sneaker bots are unusually sophisticated

These tools are considered among the most advanced consumer-facing bots on the internet because they do not simply imitate clicks in a browser. Their developers often reverse-engineer checkout flows, analyze hidden parameters, study anti-bot logic and send highly optimized requests directly to backend systems, allowing them to act faster and at much higher volume than manual buyers.

Some operators exploit hidden weaknesses

Beyond standard bypasses, attackers sometimes find poorly protected staging environments, unsecured endpoints or business-logic flaws. In one example, a luxury retailer’s free-sample system could allegedly be manipulated so restricted sneakers were treated like perfume samples, bypassing purchase limits.

Retailers cannot ignore the problem

Even when bots pay with valid cards, brands and ticketing platforms still face major risks. Legitimate buyers become frustrated and may abandon a retailer altogether, while payment processors can flag suspicious patterns such as repeated purchases across linked cards or addresses, creating operational costs and chargeback exposure.

Bots can behave like distributed denial-of-service traffic

Continuous product scanning and repeated add-to-cart attempts place heavy strain on databases and infrastructure. Because requests are spread across residential proxies rather than a few obvious IP addresses, blocking them is harder than stopping a classic DDoS attack. For some retailers, anti-bot defenses are as much about keeping the site online as about fairness.

Defense relies on browser fingerprinting and behavior analysis

Security firms inspect browser characteristics such as graphics rendering, hardware acceleration, installed fonts, execution timing and other signals to detect whether a visitor is a real person or an automated environment pretending to be one. Techniques such as canvas fingerprinting can expose inconsistencies, for example when a browser claims to be a mobile device but renders like a server-based Linux setup.

Captchas are no longer enough

Traditional image-based captchas have become easier to solve with modern machine learning. Attackers also exploit audio captchas with speech-to-text systems. As a result, defense increasingly shifts toward invisible checks that analyze device signals and user behavior, while trying not to lock out legitimate users or people relying on accessibility features.

CONCLUSION

The fight over limited-edition goods has become a high-stakes contest between highly specialized bot operators and equally specialized security teams. As long as scarcity drives resale profits, the pressure to outsmart online defenses is likely to keep growing.

Ask a question
Full transcript

More from AI